AWS Systems Manager
User Guide

The AWS Documentation website is getting a new look!
Try it now and let us know what you think. Switch to the new look >>

You can return to the original look by selecting English in the language selector above.

AWS Systems Manager Patch Manager

AWS Systems Manager Patch Manager automates the process of patching managed instances with both security related and other types of updates. You can use Patch Manager to apply patches for both operating systems and applications. (On Windows Server, application support is limited to updates for Microsoft applications.) You can patch fleets of Amazon EC2 instances or your on-premises servers and virtual machines (VMs) by operating system type. This includes supported versions of Windows Server, Ubuntu Server, Red Hat Enterprise Linux (RHEL), SUSE Linux Enterprise Server (SLES), CentOS, Amazon Linux, and Amazon Linux 2. You can scan instances to see only a report of missing patches, or you can scan and automatically install all missing patches.

Important

AWS does not test patches for Windows or Linux before making them available in Patch Manager.

Patch Manager uses patch baselines, which include rules for auto-approving patches within days of their release, as well as a list of approved and rejected patches. You can install patches on a regular basis by scheduling patching to run as a Systems Manager maintenance window task. You can also install patches individually or to large groups of instances by using Amazon EC2 tags. (Tags are keys that help identify and sort your resources within your organization.) You can add tags to your patch baselines themselves when you create or update them.

Patch Manager integrates with AWS Identity and Access Management (IAM), AWS CloudTrail, and Amazon CloudWatch Events to provide a secure patching experience that includes event notifications and the ability to audit usage.

For information about using CloudTrail to monitor Systems Manager actions, see Logging AWS Systems Manager API Calls with AWS CloudTrail.

For information about using CloudWatch Events to monitor Systems Manager events, see Monitoring Systems Manager Events with Amazon CloudWatch Events.

Getting Started with Patch Manager

To get started with Patch Manager, complete the tasks described in the following table.

Task For More Information

Verify Systems Manager prerequisites

Systems Manager Prerequisites

Learn how to set up and configure patching

Working with Patch Manager (Console)

Configure permissions for Maintenance Windows

(Required if you intend to use this feature when patching.)

Controlling Access to Maintenance Windows

Create patch baselines, patch groups, and a maintenance window to run patching in a test environment

Working with Patch Manager (Console)